//
posts

Information Security

This category contains 6 posts

Developing a Social Media Policy

At this point virtually every business has come to the realization that social media is here to stay and is an intrinsic part of how we communicate. If Facebook were a country it would be twice the size of the US. Eighty percent of companies use social media for recruitment and 95% use LinkedIn.[1] Like … Continue reading »

Information Security Acid Test

One of the more significant areas of operational risk management is a sound Information Security (IS) program.  Information security involves the risk to the business of an event that threatens the confidentiality, integrity or availability of sensitive information, whether in physical or electronic form, both internally and externally. Note that this is distinctly (and profoundly) … Continue reading »

Model Risk: The Ticking Time Bomb

I am becoming increasingly convinced that one of the most under-managed areas of risk management is model risk. Often when I see risk managers at bank conferences I pose the question, “Do you have a completed inventory of all key models used for decision making, including risk ratings and validation schedules?” This is always an … Continue reading »

7 Critical Aspects of the FFIEC Authentication Supplement

To echo the standard preamble of numerous similar articles on this subject, on June 28, 2011, the Federal Financial Institutions Examinations Council (FFIEC) released their anticipated Supplement to Authentication in an Internet Banking Environment, amending the original guidance released in 2005 and 2001.  The supplement provides updated guidance based on both recent and emerging threats … Continue reading »

The Three Corporate Functions That Should Never Be Based In IT

Within any given organization there are an almost infinite number of ways to structure departments and divisions. Depending on the industry, company type, geography, management style and other factors, a company can legitimately and logically be organized in any number of ways. Some companies prefer flat management structures, some classic hierarchical.  However, regardless of how … Continue reading »

Welcome to OpRisk Advantage!

Thank you for visiting OpRisk Advantage. Hopefully the information you find here will help you in the advancement of your own Operational Risk Management program.  Please feel free to comment on any of the content you find here, just remember to be civil, respectful and constructive.  You can also send comments, questions and topical suggestions … Continue reading »